RSA Conference: Security Issues from the Cloud to Advanced Persistent Threats

執筆者
Brian Prince
Brian Prince
Published: Feb 20, 2011
Updated: Feb 2, 2021
3 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

The 20th annual RSA Conference in San Francisco came to a close Feb. 18, ending a week of product announcements, keynotes and educational sessions that produced their share of news. This year’s hot topics: cloud computing and cyber-war.

The conference included a new session track about cloud computing, and the topic was the subject of the keynote by Art Coviello, executive vice president at EMC and executive chairman of the company’s RSA security division. Virtualization and cloud computing have the power to change the evolution of security dramatically in the years to come, he said.

“At this point, the IT industry believes in the potential of virtualization and cloud computing,” Coviello said. “IT organizations are transforming their infrastructures. … But in any of these transformations, the goal is always the same for security-getting the right information to the right people over a trusted infrastructure in a system that can be governed and managed.”

EMC’s RSA security division kicked the week off by announcing the Cloud Trust Authority, a set of cloud-based services meant to facilitate secure and compliant relationships between organizations and cloud service providers by enabling visibility and control over identities and information. EMC also announced the new EMC Cloud Advisory Service with Cloud Optimizer.

In addition, the Cloud Security Alliance (CSA) held the CSA Summit Feb. 14, featuring keynotes from Salesforce.com Chairman and CEO Marc Benioff and U.S. Chief Information Officer Vivek Kundra.

But the cloud was just one of several items touched on during the conference. Cyber-war and efforts to protect critical infrastructure companies were also discussed repeatedly. In a panel conversation, former Department of Homeland Security Secretary Michael Chertoff, security guru Bruce Schneier, former National Security Agency Director John Michael McConnell and James Lewis, director and senior fellow of the Center for Strategic and International Studies’ Technology and Public Policy Program, discussed the murkiness of cyber-warfare discussions.

“We had a Cold War that allowed us to build a deterrence policy and relationships with allies and so on, and we prevailed in that war,” McConnell said. “But the idea is the nation debated the issue and made some policy decisions through its elected representatives, and we got to the right place. … I would like to think we are an informed society, [and] with the right debate, we can get to the right place, but if you look at our history, we wait for a catastrophic event.”

Advertisement

Part of the solution is partnerships between the government and the private sector.

“One of the biggest issues you got-[and] unfortunately we haven’t made enough progress-we need better coordination across the government agencies, and from the government agencies to the private sector,” Symantec CEO Enrique Salem said. “I think we still work too much in silos inside the government [and] work too much in silos between the government and the private sector.”

The purpose of such efforts is to target advanced persistent threats (APTs).

“Part of the problem of when you define [advanced persistent threats], it’s not going to be like one single piece of software or platform; it’s a whole methodology for how bad guys attack the system,” Bret Hartman, CTO of EMC’s RSA security division, told eWEEK.

“They’re going to use every zero-day attack they can throw at you,” he explained. “They are going to use insider attacks; they’re going to use all kinds of things because they are motivated to take out whatever it is they want.”

The answer, Hartman said, is a next-generation Security Operations Center (SOC) built on six elements: This vision includes six core elements: risk planning; attack modeling; virtualized environments; automated, risk-based systems; self-learning, predictive analysis; and continual improvement through forensic analyses and community learning.

Preventing attacks also means building more secure applications. In a conversation with eWEEK, Brad Arkin, Adobe Systems’ director of product security and privacy, discussed some of the ways Adobe has tried to improve its own development process, and offered advice for companies looking to do the same.

“The details of what you do with the product team are important, but if you can’t convince the product team they should care about security, then they are not going to follow along with specifics,” Arkin said. “So achieving that buy-in to me is one of the most critical steps.”

Brian Prince

Brian Prince

Content Writer
eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。